The customer pressed send
In an authorised push payment scam, the customer passes every authentication check. The warning signs sit in the payee, the amount and the pattern. The login looks normal.



28 specialized agentsAll systems operational
Ready to transform your security infrastructure?
Explore our complete agent library and request a custom demoView All Solutions
Aiden FluxSenior AI Fraud Risk AnalystFraud Detection & Risk Scoring
Rhea LedgerSenior AI KYC/AML Compliance DirectorKYC/AML & Sanctions Screening
Nova SentinelLead AI Zero Trust Security ArchitectZero Trust Access Security
Iris VermaAI Verification SpecialistIdentity Verification & KYC
Oscar GraySenior AI OSINT Intelligence DirectorOSINT & Threat Intelligence
Bella NovaAI BNPL Risk AnalystBNPL Risk Monitoring


28 specialized agentsAll systems operational
Ready to transform your security infrastructure?
Explore our complete agent library and request a custom demoView All Solutions


28 specialized agentsAll systems operational
Ready to transform your security infrastructure?
Explore our complete agent library and request a custom demoView All Solutions
Leo Payden — Director AI Payment SecurityLeo Payden is an AI agent that watches card, account and instant payments and screens them in flight, before settlement. He scores each payment, explains the risk and holds it for review if you set him to. He also keeps evidence for your PCI DSS controls. Your payments and fraud teams make the call.

Instant payments settle in seconds and can't be pulled back. Scam victims authorise the payment themselves, so authentication passes. Each rail has its own tool and its own rules, and none of them sees the customer's whole picture.
until an instant payment settles
After that, recovery is a long shot.
In an authorised push payment scam, the customer passes every authentication check. The warning signs sit in the payee, the amount and the pattern. The login looks normal.
Card fraud tools, account payment rules and instant payment checks sit in separate systems. A fraudster who moves between them stays below each one's threshold.
Under the UK PSR APP scam reimbursement rules, in force since 7 October 2024, payment firms reimburse eligible victims up to £85,000 per claim. Every missed scam has a direct cost.
Leo Payden is a Director AI Payment Security. He sits in your payment flow across cards, accounts and instant rails, screens payments before settlement and prepares the evidence your team reviews.

We don't publish fraud capture or latency figures from our own tests. Run Leo beside your current payment controls and measure him on your rails and your volumes.
Leo Payden connects beside your systems through APIs. Your payment rails and processors stay where they are.
Payments arrive in flight from your gateway, card processor or instant payment connection, with amount, payer, payee, channel, device and originator and beneficiary details.
Leo combines a scored model with your deterministic rules and the customer's history across rails. Signals from other FluxForce agents, such as session trust from Nova Sentinel, feed the same score.
Your autonomy settings decide what happens next. Low-risk payments continue with a recorded reason if you allow it. Medium risk goes to an analyst by default. High risk always goes to an analyst, and can be held before settlement if you set it.
Every score comes with a plain-English reason and the signals behind it. The payment, the decision and the person who made it go into tamper-evident evidence storage.
Run Leo Payden in shadow mode on a copy of your payment flow. He scores and explains every payment, and nothing is held or released. Compare his calls with your current controls before you switch anything on.
Leo doesn't make you compliant. He produces the evidence these frameworks expect you to keep.
Risky payments held before settlement, where you allow it. Each with its evidence.
| CRITERIA | Processor and scheme tools | Rules engine per rail | Leo Payden |
|---|---|---|---|
| Time to first results | Already in place | Rule build per rail | Shadow mode on your live payment flow |
| Who decides | Vendor score, then analyst | Rule threshold, then analyst | Analyst, inside autonomy bands you set |
| View across rails | One rail only | One rail per engine | Cards, accounts and instant payments together |
| Why a payment was held | Vendor reason code | Rule ID | Plain-English reason with the signals behind it |
| Authorised scam signals | Limited | Only where a rule exists | Payee, amount and pattern scored on each payment |
| Where it's weaker | Can't see the rest of the customer | Static thresholds miss new scams | Screening in flight adds a step to the payment path; you test the latency on your rails in shadow mode |
Leo's screening gets sharper when other agents add what he can't see in the payment itself.

Brings monitoring alerts and the customer's behaviour baseline into Leo's score.
Meet Aiden
Settles session and device trust before the payment reaches Leo.
Meet Nova
Flags risky third-party providers initiating payments through open banking.
Meet PiersLow risk can run on its own if you allow it. Medium risk goes to a person by default. High risk always goes to a person. You set the bands per rule, channel and transaction type.
Turn Leo off without touching the other agents or your core systems. The switch, and who used it, is stamped on the record.
Run Leo on live data with nothing blocked or closed. Compare the calls with your team's before anything changes.
Every decision answers why, in plain English, with the signals and the rule or policy behind it.
Each decision is stored with its inputs, its reasoning and the person who approved it, in tamper-evident evidence storage.
Agents connect beside your systems through APIs. Your core banking, screening and case tools stay where they are.
What we're learning about AML, fraud and the evidence examiners ask for.






Talk to the people who build the agents. We'll answer per capability, yes or no.
It screens payments as they move, before settlement, for fraud and scam risk. Leo Payden scores card, account and instant payments on one view of the customer, explains each score and holds high-risk payments for review if you set him to. Your analysts make the call.
Only if you set him to hold them, and a held payment goes to an analyst. Medium risk goes to a person by default and high risk always does. Low-risk payments continue without a person only where you allow it. A kill switch turns Leo off without touching your payment rails.
He looks for the signs that come with them: a new payee, an unusual amount, a recently opened receiving account and changes in the customer's behaviour. Authentication alone can't catch these, because the customer authorises the payment.
Any check in the payment path adds some time. You measure it on your rails and volumes during shadow mode, and you choose which payments Leo screens before settlement.
We don't claim PCI DSS certification. Leo keeps evidence for the controls you align to under PCI DSS v4.0.1, such as monitoring and access to payment data. Your assessor reviews it as part of your assessment.
Leo scores a copy of your live payment flow, but nothing is held or released. You compare his calls with your current controls and with confirmed fraud. You decide whether, and where, to switch on any autonomy afterwards.
FluxForce runs as SaaS, on-premise or hybrid, built on Microsoft Azure. We agree data residency and which components run inside your environment during deployment design, before any data moves.
Run Leo Payden beside your current process. He works on your live data and records every call, and nothing is blocked, closed or sent until you decide.
Shadow mode results belong to you.
Start with one workflow in shadow mode, then decide how much each agent does on its own.